Same Origin Policy Bypass in Microsoft XML Core Services
CVE-2015-1646

Currently unrated

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
14 April 2015

Summary

Microsoft XML Core Services 3.0 is susceptible to a vulnerability that permits remote attackers to bypass the Same Origin Policy through a specially crafted Document Type Definition (DTD). This exploitation can lead to unauthorized access to sensitive data, posing significant risks to users and organizations relying on this component. It is essential for users to apply the necessary updates and patches to safeguard their systems.

References

EPSS Score

31% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.